mediumMultiple ChoiceObjective-mapped
CRISC Practice Question: During a review of third-party vendor risks, the…
During a review of third-party vendor risks, the risk team identifies that a cloud service provider's data center is located in a country with unstable political conditions. What should the risk practitioner do FIRST?
⚠ Common exam trap
The trap here is that candidates may jump to a risk treatment action (accept, mitigate, or terminate) without first completing the foundational step of documenting and assessing the risk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Document the risk and assess its potential impact.
The risk practitioner's first step should be to document the identified risk and assess its potential impact on the organization. This aligns with the CRISC framework's emphasis on risk identification and assessment before any treatment decisions are made. Without a thorough impact assessment, the organization cannot determine whether the risk is acceptable, requires mitigation, or warrants contract termination.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Document the risk and assess its potential impact.
Why this is correct
Proper risk management starts with documentation and assessment.
- ✗
Accept the risk based on the vendor's SLA.
Why it's wrong here
Acceptance requires full understanding; SLA may not cover political risks.
- ✗
Request the vendor to move data to another region.
Why it's wrong here
Action without impact assessment is premature.
- ✗
Terminate the contract immediately.
Why it's wrong here
Termination is a drastic measure; assessment should come first.
Go deeper
Related to this question
About these practice questions
One of 983 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.